
TIDoS-Framework
The Offensive Manual Web Application Penetration Testing Framework.

The Offensive Manual Web Application Penetration Testing Framework.

Go Web Application Penetration Test

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Hands-on penetration testing lab environment for CVE-2026-48282, designed for practicing exploitation and vulnerability analysis in a controlled web…

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

An intentionally designed broken web application based on REST API.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary javascript or HTML…

Web Application Exploit Development

This PoC script is designed to verify the presence of CVE-2024-9326, a high SQL Injection vulnerability in PHPGurukul Online Shopping Portal v2.0. It…

Tests your WAF with +160 payloads

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)